First published: Thu Mar 14 2024(Updated: )
It was discovered that TeX Live incorrectly handled certain memory operations in the embedded axodraw2 tool. An attacker could possibly use this issue to cause TeX Live to crash, resulting in a denial of service. This issue only affected Ubuntu 20.04 LTS. (CVE-2019-18604) It was discovered that TeX Live allowed documents to make arbitrary network requests. If a user or automated system were tricked into opening a specially crafted document, a remote attacker could possibly use this issue to exfiltrate sensitive information, or perform other network-related attacks. This issue only affected Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2023-32668) It was discovered that TeX Live incorrectly handled certain TrueType fonts. If a user or automated system were tricked into opening a specially crafted TrueType font, a remote attacker could use this issue to cause TeX Live to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2024-25262)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/texlive-binaries | <2023.20230311.66589-6ubuntu0.1 | 2023.20230311.66589-6ubuntu0.1 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/texlive-binaries-sse2 | <2023.20230311.66589-6ubuntu0.1 | 2023.20230311.66589-6ubuntu0.1 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/texlive-binaries | <2021.20210626.59705-1ubuntu0.2 | 2021.20210626.59705-1ubuntu0.2 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/texlive-binaries | <2019.20190605.51237-3ubuntu0.2 | 2019.20190605.51237-3ubuntu0.2 |
Ubuntu | =20.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
The severity of USN-6695-1 is classified as a denial of service vulnerability.
To fix USN-6695-1, you should update to the latest version of texlive-binaries or texlive-binaries-sse2 for your Ubuntu version.
USN-6695-1 affects Ubuntu 20.04 LTS, 22.04, and 23.10.
The impacted component in USN-6695-1 is the embedded axodraw2 tool within TeX Live.
USN-6695-1 cannot be exploited remotely as it primarily results in a denial of service when TeX Live processes specific memory operations.